Is FamGateway Safe?
Understanding our strict privacy policy and legal compliance to keep your data perfectly secure.
When merchants first discover FamGateway, they often ask: "If I connect my Gmail App Password, are you reading my personal emails?"
The short and definitive answer is: Absolutely not. Privacy isn't just a promise; it is hardcoded into our architecture. Below, we break down exactly how our systems operate to ensure 100% legal compliance and data security.
1. Strictly Scoped IMAP Filtering
When our Node.js daemon connects to your Gmail account via the IMAP protocol, it does not download your entire inbox. Instead, it issues a highly specific server-side search query directly to Google:
This means Google's servers only transmit emails originating from official FamPay domains. Our servers are entirely blind to any other emails—personal, promotional, or otherwise. They literally never reach our infrastructure.
2. Zero Data Retention Policy
Even for the FamPay transaction receipts that we do fetch, we employ a strict Zero Data Retention Policy.
The email body is held temporarily in RAM (server memory) just long enough to run a Regular Expression that extracts the Order ID and Amount. Once the webhook is fired to your application, the email data is instantly discarded. We do not store, log, or save the contents of your emails in our database.
3. The Power of App Passwords
You never provide us with your actual Gmail password. Instead, you generate a 16-character App Password. This acts as a revocable API key.
You remain in complete control. If you ever want to sever FamGateway's access, you simply delete the App Password from your Google Security Dashboard. The connection will instantly drop, and we will have zero ability to reconnect.
4. Legal Compliance & Authority
Because our system is mathematically restricted to fetching only transactional business receipts, we operate in full compliance with data privacy regulations. We respect your digital boundaries.